McAfee’s extended detection and response (XDR) platform is now available about three months after the security vendor first announced Mvision XDR at its annual users event.
The move follows a series of XDR product launches and updates from all of the major security firms over the last few months as the COVID-19 pandemic coupled with remote learning and work has vastly expanded the threat landscape.
To this point, more than 80% of organizations plan to increase spending on threat detection and response, according to Enterprise Strategy Group (ESG). Additionally, more than two-thirds of organizations surveyed for the ESG research said they expect to invest in XDR over the next six to 12 months, and almost half (48%) said they would be willing to replace individual security controls with integrated XDR platforms.
Why XDR?“With XDR, we are seeing an opportunity to take the SOC [security operation’s center] as we know it to the next level —moving from operating in a time and resource intense reactive manner with existing, disparate tools to using a comprehensive and integrated XDR solution that can not only proactively predict mal-activity, but also help drive faster remediation decisions with automation,” ESG senior principal analyst Jon Oltsik said in a statement.
XDR combines elements of security information and event management (SIEM), security orchestration, automation and response (SOAR), endpoint detection and response (EDR), and network traffic analysis (NTA) in a software-as-a-service (SaaS) platform to centralize security data and incident response.
“XDR wins if it excels in three areas: analytics for threat detection, strong/simple visualization, and automated response,” Oltsik said in an earlier interview with SDxCentral. “McAfee needs to be competitive in all three areas. Also, XDR will be tightly coupled to MDR [managed detection and response] services as most organizations will want some type of service support — from full outsourcing to staff augmentation. McAfee needs a strong story here, alone or with partners.”
McAfee Stuffs Insights Into XDRMvision XDR builds on several existing McAfee products including its email security, EDR, cloud, and network visibility and security technologies. It also allows customers to integrate with their existing SOC infrastructure such as ticketing systems and SOAR tools.
However, there are a couple pieces that differentiate McAfee’s XDR from its competitors. Probably the biggest one is that its XDR platform uses McAfee’s analytics engine, Mvision Insights, to provide proactive security and, thus, prevent attacks from entering an organization’s environment. Mvision Insights pulls telemetry from all of McAfee’s sensors, third-party partners, and global threat intelligence to help companies proactively prioritize threats and mitigate risks.
This predictive element is unique to McAfee, Oltsik said in an earlier interview. “So, McAfee threat intelligence detects some type of threat campaign targeting companies like mine,” he said. “It can then assess if I’m vulnerable to an attack and if my controls will be able to detect this type of attack.”
In addition to Insights, Mvision XDR uses artificial intelligence (AI), which McAfee says helps guide investigations and provide real-time threat hunting.
Who Will Win the XDR Race?This focus on AI for XDR sounds similar to Fortinet’s strategy also unveiled this week. FortiXDR uses AI for threat response and threat investigations, which the vendor claims can fully automate security operations processes from detection to investigation and remediation.
In addition to McAfee and Fortinet, major vendors including Cisco, Palo Alto Networks, VMware, and Microsoft all rolled out XDR platforms or platform updates over the past few months. Other security providers like CrowdStrike and Cybereason, for example, that provide EDR but not all of the other XDR components have moved ahead with more of a partnership approach.
“The interesting angle here is whether organizations will go single vendor or demand some type of heterogeneous architecture,” Oltsik said in an earlier interview. “We’ll see.”
Comments